The JSST and the Joomla! Security Center report:
[20161201] - Core - Elevated Privileges
Incorrect use of unfiltered data stored to the session on a form
validation failure allows for existing user accounts to be modified;
to include resetting their username, password, and user group
assignments.
[20161202] - Core - Shell Upload
Inadequate filesystem checks allowed files with alternative PHP
file extensions to be uploaded.
[20161203] - Core - Information Disclosure
Inadequate ACL checks in the Beez3 com_content article layout
override enables a user to view restricted content.